MAL-2026-13478

    Dashboard / Malicious Package / MAL-2026-13478

    MAL-2026-13478

    Published: 6 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in @cats-cdf/authentication (npm)

    Details: Source: amazon-inspector (404569337a1e5fc46fff2584e052d2f9f99c3cb8d04e5fb3b5c5d633c178e01c) The package's preinstall lifecycle script runs on npm install and collects the installer's local username (whoami), hostname, and public IP address (fetched via ifconfig.me), then transmits them as query-string parameters in an HTTP GET request to a hardcoded subdomain of oast.fun (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun). oast.fun is an out-of-band interaction/callback service commonly used for reconnaissance and exfiltration in dependency-confusion attacks. The behavior fires automatically on default install with no relation to any documented package purpose.

    Affected packages

    Package

    Name: @cats-cdf/authentication

    Purl: pkg:npm/%40cats-cdf/authentication

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.1.1
    MAL-2026-13478 | CVE-DB